Forum Discussion
Link controller design
hello, i am having a concern on my link controllers for inbound load balancing. i have my design to be simply as this
( internet with public IP's)
then
firewall ( public IP from external and local IP from internal)
then
F5 link controller ( local IP's from External and local IP's from Internal)
.we have done all the outbound traffic to work as well as the inbound traffic. my concern is load balancing inbound traffic how would the link controller reply to DNS queries on my wide IP if all my virtual servers ( for hosted applications) have local IP addresses. is there a work around for that.
Kind Regards walid
2 Replies
- HHeredia_36237
Nimbostratus
I think that's not the apropiate way to deploy LC for inbound traffic at least. As you state, the LC start to resolve WIDE (FQDN) to one of the Virtual Servers you have, so if they were private addresses, what user would get is an unreachable IP for the looked up domain so you may want to reconsider your desing an put the LC over the FW, use it's corresponding public IP addr. and get firewall a new private IP assingment to be used between it and the F5.
Good luck,
HHeredia - elvis_chavezg_1
Nimbostratus
Hello HHeredia In this case, is necesary double NAT in the network, so one NAT private to new private in Firewall and other nat of new-private to Public ip in the LC?
best regards
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com